Our mission
d2defence was founded by security engineers and machine learning researchers who had spent their careers on the wrong side of the alert queue — watching teams triage by hand while attackers moved in seconds.
We build autonomous security agents that close that gap: they detect the threat, decide what actually matters, and defend the estate, with every action logged and reversible.
Founded
Products, one Autonomous AI Engine
Engineers and researchers
Engineering hubs
01 / How we work
Four positions that decide what we build and, more often, what we refuse to.
01 / Principle
Agents act on the reversible, well-evidenced cases without waiting for a human. Every autonomous action is logged, attributable, and reversible — autonomy without accountability is just risk.
02 / Principle
An alert is a hypothesis; proof is a finding. We ship products that demonstrate exploitability with verified execution rather than adding another queue for someone to grade.
03 / Principle
A credential flagged in one product should revoke a session in another. Shared context is the whole argument for a platform — otherwise it is just point tools with the same invoice.
04 / Principle
Dwell time is the damage. We treat the gap between detection and containment as the number that matters, and we publish it rather than hiding behind feature counts.
02 / Trajectory
2021
Started by security engineers and ML researchers who had spent years on the wrong side of the alert queue.
2022
Shipped the Autonomous AI Engine that correlates endpoint, identity, and secrets telemetry into a single decision.
2024
Seven products consolidated onto one Autonomous AI Engine, with cross-product response replacing disconnected alerts.
2026
Full detect-decide-defend loop in production, containing well-evidenced incidents without human approval.